Questions tagged [malware-detection]

67 questions
13
votes
1 answer

uTorrent - adware / malware on download and install - Mac OSX Yosemite

I recently downloaded uTorrent (for the more ethically concerned: to get a wikipedia data dump as the official download server kept terminating my download, not to rip off copyright holders...), and as soon as the installation had finished my…
10
votes
5 answers

How can I make my OS appear as if it is running virtualized?

A lot of malware these days is able to detect when it is running virtualized under VMWare, VirtualPC, WINE, or even in a sandbox such as Anubis or CWSandBox. This essentially means that malware will often "hold back" or not function maliciously when…
Mick
  • 1,961
9
votes
4 answers

How can you find out if xlsx and docx files are safe to open?

I have received an email from a not entirely trustworthy source, it might be legit but I'm not really sure. It contains, among other things, information on a .docx Microsoft Word file and a .xlsx Microsoft Excel file. I have already scanned the…
fightermagethief
  • 863
  • 4
  • 12
  • 26
7
votes
2 answers

csrss.exe anomalies, is this a rootkit?

I'm seeing a strange anomaly in some systems I support. GMER flags the cdd.dll thread in csrss.exe, and when I run Process Explorer with Elevated Admin rights, I am: unable to view any loaded DLLs in either csrss.exe process unable to view actual…
6
votes
2 answers

What's the difference between traditional and heuristic virus scanning?

I just got off the phone with one of the major AV companies as to why a lesser known AV caught a virus that theirs didn't. The details of that delima are not important. What caught my attention about the conversation was when the technician made…
5
votes
0 answers

Is this a ransomware?

I just got this window on my main computer: Apparently, it's from Windows. I checked, and the process EXE file is the original one (efsui.exe or something like that). However, I don't use EFS (I never heard about it). I never encrypted any of my…
zdimension
  • 14,283
4
votes
3 answers

How do I properly check if a program is a virus/trojan in VMware?

How I should check if a program is a virus in VMware? Some programs I do need admin ability to install and it makes sense. But how do I know if it's doing more than I want? Some thoughts are: How many processes open when I launch the…
user3109
4
votes
2 answers

What is this Firefox hidden add-on: "Add-ons Search Detection (addons-search-detection@mozilla.org)"?

In Firefox 95.0.1 task manager, I see the following item: "Add-ons Search Detection (addons-search-detection@mozilla.org)" with full permissions to all browsing and private tabs. What is this plugin? What does it do and should it be removed? Note…
4
votes
0 answers

How to protect Linux from Ransomware by detecting mass changes?

I wonder if it would be possible to stop running ransomware on a Linux system by detecting mass changes on files. Can watchdog or entr or inotifywait be used to detect bulk file changes and stop what is going on by a ransomware? Here is a discussion…
3
votes
2 answers

what does it mean for MalwareBytes to find malicious registry keys but nothing else?

I have a machine that is obviously infected, and when I ran MalwareBytes it told me that it found some "malicious" registry keys (surprisingly enough these contained file path to currently non-existent javascript files). But, that's it. Full scan…
3
votes
1 answer

How to catch a malware process on my Mac?

Situation: 1st occurrence: without reason a new draft in mail opened up with non-sense text in the body, no TO,CC or subject 2nd and reoccurring every day around 2 PM: bing search with non-sense text the text slightly changes but most of the time…
Sven
  • 301
3
votes
2 answers

How can I detect what causes Chrome to open a tab for "http://eaes.2track.info/" each time I search something in the address bar?

How can I detect what causes Chrome to open a tab for "http://eaes.2track.info/" each time I search something in the address bar? Interestingly this only happens for the first few searches I do after starting the Windows. Afterward it doesn't open a…
Franck Dernoncourt
  • 24,246
  • 64
  • 231
  • 400
2
votes
0 answers

Detect and remove malicious malware chrome extension that opens many tabs with ads

I observed throughout the day yesterday three episodes where my processor gets hijacked for a minute and the memory gets maxed out (12 gigs). The culprit was a seemingly infinite number of tabs being opened in one of the Google Chrome windows with…
2
votes
4 answers

How can I remove http://p.chango.com/static/c.js from my site?

I found some code injected somehow on my site. It links to